Check Point issued emergency updates for two critical vulnerabilities, CVE-2026-85102 and CVE-2026-85103, affecting Quantum Security Gateways, Security Management systems, Spark Firewalls, and Remote Access and Site-to-Site VPN deployments. An unauthenticated attacker could exploit flaws in certificate handling during VPN negotiation to execute arbitrary code on exposed perimeter appliances; CVE-2026-85102 involves improper certificate validation and authentication bypass, while CVE-2026-85103 is a heap overflow in ASN.1 certificate decoding.
Check Point has provided fixes through LivePatch and Jumbo Hotfix Accumulator packages. Organizations should apply available updates promptly and, where patching is delayed, reduce VPN exposure using implied-rule and UDP-port controls. No public proof-of-concept exploit was reported at disclosure, but internet-facing VPN infrastructure is a high-priority remediation target.

Map this exposure pattern across your cloud, code, and identities.
2 events from the most recent confirmed update back to the earliest known activity.
The Canadian Centre for Cyber Security issued advisory AV26-902 covering CVE-2026-85102, an authentication-bypass and remote-code-execution issue in Remote Access and Site-to-Site VPN, and CVE-2026-85103, an ASN.1-decoding heap overflow that can lead to remote code execution. The advisory identified affected Check Point Security Gateway, Spark Firewall, and Security Management Server products and urged administrators to apply available updates.
Check Point released emergency updates for CVE-2026-85102 and CVE-2026-85103, which affect VPN certificate processing in Quantum Security Gateway, Security Management, and Spark Firewall products. The fixes were provided through LivePatch and Jumbo Hotfix Accumulator packages; both flaws can permit unauthenticated remote code execution.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See where this exposure pattern shows up across your cloud, code, supply chain, and non-human identities.
3 references tracked. Mallory keeps watching after this page renders.
malware.news
Open sourcecyber.gc.ca
Open sourcelabs.beazley.security
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.